CLAIMS 



10 



15 



20 



25 



A method of capturing a security breach, comprising: 
deploying a honey pot; 
detecting a breach of the honey pot; and 
automatically redeploying the honey pot. 

further including analyzing the breach, 
further including automatically analyzing the breach, 
wherein the breach is automatically detected, 
further including copying state information from the 



further including shutting down the honey pot. 
further including configuring the honey pot. 
further including copying a honey pot image, 
wherein the honey pot is a physical machine, 
wherein the honey pot is a virtual machine, 
wherein the honey pot is a VMware virtual machine, 
wherein the honey pot is a Microsoft Virtual PC virtual 

wherein detecting is based on the number of outgoing 

wherein detecting is based on the number of incoming 

wherein detecting is based on an elapsed time, 
wherein the honey pot runs a Windows operating system, 
wherein the honey pot runs a Linux operating system, 
further including saving state information associated with 
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The method of claim 
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The method of claim 


4. 


The method of claim 
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The method of claim 


honey pot. 
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The method of claim 
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The method of claim 
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The method of claim 
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The method of claim 
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machine. 


13. 


The method of claim 


connections detected. 
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connections detected. 
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The method of claim 
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The method of claim 
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The method of claim 
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The method of claim 


the honey pot. 


19. 


The method of claim 



the honey pot and wherein saving and redeploying occur in parallel. 
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20. The method of claim 1, further including analyzing the breach and wherein 
analyzing and redeploying occur in parallel. 

21 . The method of claim 1 , further including: 

receiving an incoming connection associated with an IP address; 
mapping the IP address to the honey pot; and 
releasing the IP address mapping. 

22. The method of claim 1, further including: 

receiving an incoming connection associated with an IP address; 
mapping the EP address to the honey pot; 
releasing the IP address mapping; and 
mapping another IP address to the honey pot. 

23. A computer program product for capturing a security breach, the computer 
program product being embodied in a computer readable medium and comprising 
computer instructions for: 

deploying a honey pot; 

detecting a breach of the honey pot; and 

automatically redeploying the honey pot. 

24. A system for capturing a security breach, comprising: 
a processor configured to: 

deploy a honey pot; 
detect a breach of the honey pot; and 
automatically redeploy the honey pot; and 
a memory coupled with the processor, wherein the memory provides the 
processor with instructions. 
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